Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
- ID
- 21808
- Status
- summarized
- Published
- 06 Sep 2026, 12:05 AM
- Fetched
- 06 Sep 2026, 1:09 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 06 Sep 2026, 1:10 AM
- Tags
- Audience
- developersvibe_coders
What happened
Broadcom patched two VMware Workstation and Fusion vulnerabilities (CVE-2026-59346, CVSS 9.3; CVE-2026-59347, CVSS 8.1) that let a local admin inside a VM execute code on the host machine. Both affect versions 25H2 and 26H1, with no workarounds available; fixes shipped in VMware Workstation and Fusion 26H1u1.
Why it matters
If you run VMware Workstation or Fusion for local dev or testing on versions 25H2 or 26H1, update to 26H1u1 now — a compromised VM can escape to your host. This matters most for anyone running untrusted code or multi-tenant VMs locally; if your VMs are single-user and trusted, the risk is lower since exploitation requires existing local admin inside the VM.
Discussion angle
How many of us still run local desktop hypervisors (VMware Workstation/Fusion) versus containers or cloud VMs, and does VM-to-host escape change that calculus for anyone running untrusted code locally?